Licensing and repository identity are clear, while the project offers little operational safety documentation. Organization backing helps, but the small release history provides limited evidence of sustained maintenance.
61%
Total Score
75
86
75
Only two releases have appeared across 919 days, with one release in the last 12 months and a median interval of about 581 days. This is a thin maintenance record, though the recent 1.1.0 release shows the project is not wholly abandoned.
The repository recorded zero commits and zero active maintainers in the last three months. Although the latest release was recent, there is little current evidence of active maintenance.
Composer is used for the build, but no security-scanning tool was detected. This is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no security policy. That leaves vulnerability-reporting expectations unclear, which modestly lowers project transparency.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.